Courseiva
Design for New Solutions →mediumMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A healthcare company is designing a new application that must store protected health information in Amazon DynamoDB. The compliance team requires that all data be encrypted at rest with a customer-managed AWS KMS key so that key rotation and access can be audited centrally. The application runs on Amazon EC2 instances in a private subnet and must access the table over a private network path. The solutions architect needs to configure encryption and network access. Which combination of steps should the architect take?

⚠ Common exam trap

Candidates often confuse DynamoDB VPC endpoint types and selecting an interface endpoint, when DynamoDB uses gateway endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a DynamoDB table with a customer-managed KMS key, and create a gateway VPC endpoint for DynamoDB; attach an endpoint policy that restricts access to the specific table.

Using a customer-managed KMS key for the DynamoDB table meets the compliance requirement for auditable, rotatable encryption. A gateway VPC endpoint for DynamoDB provides private connectivity from the VPC, and an endpoint policy can restrict access to the specific table, satisfying the private network requirement without exposing traffic to the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a DynamoDB table with a customer-managed KMS key, and create a gateway VPC endpoint for DynamoDB; attach an endpoint policy that restricts access to the specific table.

    Why this is correct

    A customer-managed KMS key satisfies the audit and rotation requirement, and a gateway VPC endpoint provides private connectivity from the VPC to DynamoDB without internet access. An endpoint policy can restrict access to the specific table, adding least-privilege control. This combination meets both encryption and network requirements.

  • ✗

    Create a DynamoDB table with a customer-managed KMS key, and create an interface VPC endpoint for DynamoDB; attach an endpoint policy allowing access to the table.

    Why it's wrong here

    DynamoDB uses gateway VPC endpoints, not interface endpoints, for private access from a VPC. An interface endpoint uses AWS PrivateLink and is not the supported mechanism for DynamoDB. Although the encryption choice is correct, the network access method is wrong, so the design would not work as described.

  • ✗

    Create a DynamoDB table with a customer-managed KMS key, and configure the application to use the DynamoDB Accelerator (DAX) cluster in the VPC for private access.

    Why it's wrong here

    DAX is an in-memory cache for DynamoDB and does not provide the private network path to the DynamoDB service itself; DAX still connects to DynamoDB over the network. It also adds cost and complexity without addressing the requirement for a private endpoint. The encryption choice is correct, but DAX is not a substitute for a VPC endpoint.

  • ✗

    Create a DynamoDB table with an AWS owned key, and create a VPC endpoint for DynamoDB; use the default endpoint policy.

    Why it's wrong here

    AWS owned keys are not customer-managed and cannot be audited or rotated by the customer, so this fails the compliance requirement. A VPC endpoint does provide private access, but the encryption choice is wrong. The scenario explicitly requires a customer-managed KMS key, so this option does not satisfy the design.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.